← Back

Onosproject

onosproject

15 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onosproject
1Traffic Steering Xapplication
Jun 27, 2025
Apr 30, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.
1Onosproject
1Traffic Steering Xapplication
May 27, 2025
Apr 30, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.
1Onosproject
1Onos
Jan 29, 2025
May 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter...Show more
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.Show less
1Onosproject
1Onos
Nov 21, 2024
Jul 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
1Onosproject
1Onos
Nov 21, 2024
Jul 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result...Show more
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.Show less
1Onosproject
1Onos
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a...Show more
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a normal switch.. This attack appear to be exploitable via the attacker should be able to control or forge a switch in the network..Show less
1Onosproject
1Onos
Nov 21, 2024
Jul 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslator.java that can resu...Show more
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslator.java that can result in An adversary can remotely launch advanced XXE attacks on ONOS controller without authentication.. This attack appear to be exploitable via crafted protocol message.Show less
1Onosproject
1Onos
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.8 MEDIUM· v3
4.3 MEDIUM· v2
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection...Show more
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.Show less
1Onosproject
1Onos
May 13, 2026
Aug 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
1Onosproject
1Onos
May 13, 2026
Aug 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
1Onosproject
1Onos
May 13, 2026
Aug 24, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Frame (0x8870).
1Onosproject
1Onos
May 13, 2026
Jul 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
1Onosproject
1Onos
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
1Onosproject
1Onos
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
1Onosproject
1Onos
May 13, 2026
Jul 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration